www.cisa.gov 3/13/2026, 7:36:16 PM · via preferred

CISA Adds CVE-2026-3909 to Known Exploited Vulnerabilities Catalogue

CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to Known Exploited Vulnerabilities Catalog, CVE-2026-3909 is a Google Skia out-of-bounds write vulnerability that could allow a remote attacker to perform memory access via a crafted HTML page. This flaw affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products, with a related CWE of 787. The entry notes that it is unknown whether it has been used in ransomware campaigns.

Action items include applying mitigations per vendor instructions, following applicable BOD 22-01 guidance for cloud services, or discontinuing use of the affected product if mitigations are unavailable. The vulnerability was added to the catalog on 13 March 2026, with a due date of 27 March 2026. Additional information points to a Chrome releases blog and the NIST NVD entry for CVE-2026-3909.

View Primary Source Via www.cisa.gov

Article by CyberSIXT